{"id":3675,"date":"2022-10-02T06:06:48","date_gmt":"2022-10-02T06:06:48","guid":{"rendered":"https:\/\/itegriti.com\/kw022024\/?page_id=3675"},"modified":"2022-10-02T17:06:19","modified_gmt":"2022-10-02T17:06:19","slug":"cybersecurity-in-the-electricity-industry","status":"publish","type":"page","link":"https:\/\/itegriti.com\/kw022024\/expertise\/cybersecurity-in-the-electricity-industry\/","title":{"rendered":"Cybersecurity in the Electricity Industry"},"content":{"rendered":"<p><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-1 fusion-flex-container has-pattern-background has-mask-background hundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-padding-top:0px;--awb-padding-right:0px;--awb-padding-bottom:0px;--awb-padding-left:0px;--awb-margin-bottom:0px;--awb-background-color:#0d3579;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"width:104% !important;max-width:104% !important;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-0 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-padding-top:0px;--awb-padding-right:0px;--awb-padding-bottom:0px;--awb-padding-left:0px;--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\">\t\t\t\t\t<div class=\"fusion-slider-container fusion-slider-sc-expertise-electricity fusion-slider-2202 full-width-slider\" style=\"height:300px; max-width:100%;\" data-id=\"2202\" data-full_height=\"\">\n\t\t\t\t\t\t<style type=\"text\/css\">.fusion-slider-2202 .flex-direction-nav a {width:63px;height:63px;line-height:63px;font-size:25px;}<\/style>\t\t\t\t\t\t<div class=\"fusion-slider-loading\">Loading...<\/div>\n\t\t\t\t\t\t<div class=\"tfs-slider flexslider main-flex full-width-slider\" data-slider_width=\"100%\" data-slider_height=\"300px\" data-full_screen=\"0\" data-parallax=\"0\" data-nav_arrows=\"0\" data-nav_arrow_size=\"25px\" data-nav_box_width=\"63px\" data-nav_box_height=\"63px\" data-slideshow_speed=\"7000\" data-loop=\"0\" data-autoplay=\"1\" data-orderby=\"date\" data-order=\"DESC\" data-animation=\"fade\" data-animation_speed=\"600\" data-typo_sensitivity=\"1\" data-typo_factor=\"1.5\" style=\"max-width:100%;\">\n\t\t\t\t\t\t\t<ul class=\"slides\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li data-mute=\"yes\" data-loop=\"yes\" data-autoplay=\"yes\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"slide-content-container slide-content-left\" style=\"display: none;\">\n\t\t\t\t\t\t\t\t\t\t\t<div class=\"slide-content\" style=\"\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"heading \">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"fusion-title-sc-wrapper\" style=\"\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"fusion-title title fusion-title-1 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-text-color:var(--awb-color1);--awb-margin-bottom:0px;--awb-sep-color:var(--awb-color1);--awb-font-size:50px;\"><h2 class=\"fusion-title-heading title-heading-left fusion-responsive-typography-calculated\" style=\"margin:0;font-size:1em;--fontSize:50;line-height:1.2;\">Electricity Industry<\/h2><\/div>\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"caption \">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"fusion-title-sc-wrapper\" style=\"\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"fusion-title title fusion-title-2 fusion-sep-none fusion-title-text fusion-title-size-three\" style=\"--awb-text-color:var(--awb-color1);--awb-margin-bottom:0px;--awb-sep-color:var(--awb-color1);--awb-font-size:24px;\"><h3 class=\"fusion-title-heading title-heading-left fusion-responsive-typography-calculated\" style=\"margin:0;font-size:1em;--fontSize:24;line-height:1.2;\"><sup><h7 style=\"color:white;font-size:16px;\"><\/h7><\/sup><\/h3><\/div>\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"background background-image lazyload\" style=\"background-image:inherit;max-width:100%;height:300px;filter: progid:DXImageTransform.Microsoft.AlphaImageLoader(src='https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/10\/Itegriti_electricity1_hdr.jpg', sizingMethod='scale');\" data-imgwidth=\"1950\" data-bg-image=\"url(https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2022\/10\/Itegriti_electricity1_hdr.jpg)\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-2 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-color:var(--awb-color8);--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-justify-content-center fusion-flex-content-wrap\" style=\"max-width:1216.8px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-1 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-blend:overlay;--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:40px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-3 fusion-sep-none fusion-title-text fusion-title-size-one\" style=\"--awb-text-color:var(--awb-color8);--awb-margin-bottom:-40px;\"><h1 class=\"fusion-title-heading title-heading-left fusion-responsive-typography-calculated\" style=\"margin:0;--fontSize:50;line-height:1.29;\"><h1><span style=\"color: #002868;\">Cybersecurity in the Electricity Industry<\/span><\/h1><\/h1><\/div><div class=\"fusion-text fusion-text-1\" style=\"--awb-text-transform:none;\"><h2>What Is the Electricity Industry?<\/h2>\n<p>The electricity industry is a type of national critical infrastructure that\u2019s \u201cnecessary to maintain normalcy in daily life,\u201d as stated by the U.S. Department of Homeland Security.<a href=\"#_edn1\" name=\"_ednref1\">[1]<\/a> In total, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) identified 16 critical infrastructure sectors whose systems and networks are vital to national security and public health in the United States.<a href=\"#_edn2\" name=\"_ednref2\">[2]<\/a> Energy is one of those sectors. It comprises electricity, oil, and natural gas.<a href=\"#_edn3\" name=\"_ednref3\">[3]<\/a><\/p>\n<p>CISA noted that the U.S. electricity sector consists of over 6,413 power plants and that 48% of the nation\u2019s electricity comes from coal combustion. This was followed by natural gas combustion, nuclear power, hydroelectric plants, renewable sources, and oil at 22%, 20%, 6%, 3%, and 1%, respectively. Moreover, CISA noted that many if not all other industries including critical infrastructure industries depend on the electricity sector, making electric utilities and the power they provide important fixtures of modern life.<\/p>\n<h2>How Fast Is the Electricity Industry Growing?<\/h2>\n<p>Electricity sales increased 3.8% through August 2021 over the previous year.<a href=\"#_edn4\" name=\"_ednref4\">[4]<\/a> The International Energy Agency (IEA) went on to report that global electricity demand had grown 6% by the end of 2021, constituting the largest rise in percentage terms since 2010. It also noted an increase of 1,500 terawatt hours in absolute terms for the year. Approximately half of this growth took place in China, where demand increased by 10%. Electricity produced by renewable sources rose by 6% during the same period.<a href=\"#_edn5\" name=\"_ednref5\">[5]<\/a><\/p>\n<p>Looking ahead, IEA anticipates that electricity demand will grow an average of 2.7% each year. Renewables will constitute 90% of net demand growth during that period, with annual growth estimated at 8%. Meanwhile, IEA expected nuclear-based generation to grow 1% a year.<a href=\"#_edn6\" name=\"_ednref6\">[6]<\/a><\/p>\n<h2>What Are Some of the Risks Facing Electricity Organizations?<\/h2>\n<p>First, the convergence of Information Technology (IT) and Operational Technology (OT) opens opportunities for attack. Organizations can use connected sensors, Industrial Internet of Things (IIoT) devices, and other products to monitor the performance of their OT assets, conduct preventative maintenance, and maximize uptime. But there\u2019s a flip side to the <a href=\"https:\/\/itegriti.com\/kw022024\/2020\/cybersecurity\/industrial-control-systems-are-being-targeted-by-ransomware-attacks\/\">IT-OT convergence<\/a>. Many OT systems use legacy software and hardware that\u2019s decades old and that can\u2019t receive updates remotely. This means the systems are susceptible to well-known vulnerabilities that digital attackers can use to establish a foothold into a victim\u2019s network and pivot to business-critical assets.<\/p>\n<p>There\u2019s also the use of satellite Global Positioning System (GPS). The electric grid needs signals delivered by GPS to synchronize the transmission and distribution of electricity as well as to report on potential issues in real time.<a href=\"#_edn7\" name=\"_ednref7\">[7]<\/a> The problem is that malicious actors can capture unencrypted GPS signals in civilian applications. Depending on the types of technologies used at electric utilities, malicious actors can leverage that opportunity to conduct GPS spoofing attacks and broadcast a fake signal. This can provide electric utilities with false insights into the state of the electric grid, providing cover which nefarious individuals can use to create blackouts.<\/p>\n<p>Finally, electric utilities\u2019 supply chains continue to grow in complexity. Many organizations in the sector now purchase equipment from manufacturers in Taiwan, Singapore, China, South Korea, and elsewhere. protection standards and compliance frameworks than those in the United States and Europe. Depending on the strength of those commitments, malicious actors could use certain oversights to compromise essential hardware and software for the purpose of gaining access to customers\u2019 networks and systems.<\/p>\n<h2>What Motivations Do Attackers Have for Targeting Electricity?<\/h2>\n<p>Some attackers are intent on disrupting the availability and reliability of electricity in certain countries. Doing so can <a href=\"https:\/\/itegriti.com\/kw022024\/2020\/cybersecurity\/industrial-control-systems-are-being-targeted-by-ransomware-attacks\/\">harm the host country\u2019s national and global economy<\/a>. These types of effects can benefit another utility that\u2019s looking to undermine the reputation of a competitor. They can also work to the advantage of a nation-state that sponsors digital attackers as part of an interstate conflict.<\/p>\n<p>That said, individuals who target electric utilities and other energy organizations tend to fit a certain profile. <a href=\"https:\/\/itegriti.com\/kw022024\/2021\/managed-services\/verizon-data-breach-report-2021-healthcare-energy-and-smbs-have-it-rough\/\">Most (98%) of them are external actors<\/a>, with at least 78% of those attackers motivated by financial gains. Threat actors can capitalize on an attack against an electric organization by stealing data, selling it to a competitor, and\/or handing it to a state sponsor.<\/p>\n<h2>How Are Attackers Targeting Electricity?<\/h2>\n<p>Three security incidents help to illustrate various ways that malicious actors are targeting entities in the electricity sector. One of those incidents was the <a href=\"https:\/\/itegriti.com\/kw022024\/2021\/cybersecurity\/supply-chain-risk-management-in-electric-grid-utilities\/\">SolarWinds supply chain attack<\/a>. As a reminder, malicious actors infiltrated a software update distribution channel used by the company and abused it to push out malware to approximately 18,000 users. Once active, the malware attempted to contact a command and control (C&amp;C) server operated by the attackers. If successful, this connection enabled the campaign\u2019s operators to enter an affected organization\u2019s network and perform follow-up attacks like dropping additional malware payloads. Indeed, of those 18,000 victims, nearly 2,000 experienced a Sunburst malware infection, with a third of those organizations based in electricity and other industrial sectors.<\/p>\n<p>The incident discussed above wasn\u2019t the only time that attackers targeted partners, suppliers, and third parties serving the electric grid. On May 14, 2020, Elexon, which administers the Balancing and Settlement Code (BSC) in the UK, that it had fallen victim to a digital attack. The incident affected the company\u2019s internal IT network and employee laptops along with its email server, though it did not disrupt systems responsible for managing the transit of the United Kingdom\u2019s electricity. Elexon didn\u2019t clarify the source of the attack in a statement posted to its website, but some experts thought that ransomware had been responsible.<a href=\"#_edn8\" name=\"_ednref8\">[8]<\/a><\/p>\n<p>There were other instances in which digital attackers targeted electric organizations directly, however. Around Christmas Day 2015, for example, malicious actors entered the supervisory control and data acquisition (SCADA) networks used by Prykarpattyaoblenergo, an electric power distributor for the Ivano-Frankivsk in western Ukraine. The attackers used a phone-based denial-of-service (DoS) attack against customer call centers as cover to open breakers and take some substations off the grid. They also overwrote legitimate firmware with malicious code, rendering the converters unrecoverable, and leveraged malware called \u201cKillDisk\u201d to wipe the operator stations.<a href=\"#_edn9\" name=\"_ednref9\">[9]<\/a><\/p>\n<h2>What Standards and Frameworks Apply to<\/h2>\n<p>There are two major sets of standards that apply to electric organizations. The first is ISA\/IEC 62443. This framework isn\u2019t specific to the electricity sector. It seeks to address the challenges that electric utilities. pipeline companies, petroleum production plants, distribution facilities, and other organizations might face when attempting to secure their industrial automation and control systems (IACS) along with other assets in their OT environments. It does this by providing organizations with reference architectures by which they can build cybersecurity into their networks along with direction for crafting security processes and cybersecurity management systems (CSMS).<a href=\"#_edn10\" name=\"_ednref10\">[10]<\/a><\/p>\n<p>The second set of standards relevant to electric organizations is the North American Electric Reliability Corporation\u2019s Critical Infrastructure Protection (NERC CIP). The suite includes requirements that electric organizations in North America can use to secure their systems against digital threats like cyberterrorism and state-sponsored attacks. The standards include <a href=\"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/an-introduction-to-nerc-cip-013-1\/\">CIP-013-1<\/a>, which requires organizations with bulk electric system (BES) Cyber Systems to implement a supply chain risk management program. They also cover <a href=\"https:\/\/itegriti.com\/kw022024\/2020\/compliance\/the-ultimate-implementation-guide-for-nerc-cip-008-6\/\">CIP-008-6<\/a>, a control which mandates that in-scope entities meet certain incident response requirements.<\/p>\n<h1><\/h1>\n<p>Electric utilities can do several things to minimize the risk of a hack. First, they can focus on <a href=\"https:\/\/itegriti.com\/kw022024\/2021\/compliance\/6-steps-to-nerc-cip-013-1-compliance-the-ultimate-checklist\/\">achieving visibility of their assets<\/a>\u2014particularly software components within their applications. Organizations can do that by creating a Software Bill of Materials (SBOM) and investigating for potentially dangerous components, software dependencies, and supply chain risks. They can also use periodic walkdowns to verify that their inventories on file reflect what\u2019s actually deployed across their environments.<a href=\"#_edn11\" name=\"_ednref11\">[11]<\/a> With an accurate inventory in hand, electric utilities can then go about <a href=\"https:\/\/itegriti.com\/kw022024\/2022\/managed-services\/how-electricity-organizations-can-minimize-the-possibility-of-a-hack\/\">patching vulnerabilities in those authorized devices on a timely basis<\/a>.<\/p>\n<p>Next, they need to work to eliminate information silos. Utilities can do this by requiring leaders of relevant business leaders to participate in group meetings around digital security topics. Doing so will help to provide all stakeholders with a voice in the decision-making process so that organizations can create a holistic plan and allocate resources effectively.<a href=\"#_edn12\" name=\"_ednref12\">[12]<\/a><\/p>\n<p>Third, organizations in the electricity sector can segment their IT and OT networks. This will help to prevent malicious actors from exploiting a vulnerable IIoT device for the purpose of accessing and tampering with OT assets.<\/p>\n<p>Finally, electric utilities must avoid thinking of themselves as insulated entities. They might face unique challenges in terms of geography and local legislation, but they largely face similar digital threats. That\u2019s why they might consider working together with industry peers and government agencies. By participating in drills such as NERC\u2019s GridEx or the EIS Council\u2019s transnational EarthEx exercise, these organizations can exchange intelligence on threats and vulnerabilities as well as hone their own company-wide defense plans.<a href=\"#_edn13\" name=\"_ednref13\">[13]<\/a><\/p>\n<h2>How Can Electricity Organizations Maintain a Strong Security Culture?<\/h2>\n<p>Aside from the measures described above, electric utilities must also take steps to <a href=\"https:\/\/itegriti.com\/kw022024\/2020\/cybersecurity\/creating-organizational-cybersecurity-culture\/\">build and maintain a strong security culture<\/a>. They can do this by designating groups of \u201ccybersecurity champions\u201d within each business unit to help document employees\u2019 security behavior Once they have that understanding, organizations can select behaviors they\u2019d like to address and work with the cybersecurity champions as well as through an ongoing security awareness training program to change those behaviors over time.<\/p>\n<p>This can be difficult for some electricity organizations to do on their own. That\u2019s where <a href=\"https:\/\/itegriti.com\/kw022024\/managed-services\/\">Itegriti<\/a> comes in. ITEGRITI is a cybersecurity consulting and advisory firm with deep expertise gained through our work in protecting large-scale and distributed National Critical Infrastructure since those Standards first became mandatory in 2008. The cybersecurity resilience programs we develop will help you avoid hacks, detect breaches, minimize business disruption during an event, and reduce incident recovery time. They will also help you to <a href=\"https:\/\/itegriti.com\/kw022024\/2022\/managed-services\/build-cybersecurity-into-your-compliance-not-the-other-way-around\/\">build cybersecurity into your compliance programs<\/a>.<a href=\"#_ednref1\" name=\"_edn1\"><\/a><\/p>\n<\/div><div class=\"fusion-separator\" style=\"align-self: flex-start;margin-right:auto;margin-top:15px;margin-bottom:15px;width:100%;max-width:60%;\"><div class=\"fusion-separator-border sep-single sep-solid\" style=\"--awb-height:20px;--awb-amount:20px;border-color:#e0dede;border-top-width:1px;\"><\/div><\/div><div class=\"fusion-text fusion-text-2\" style=\"--awb-text-transform:none;\"><p><a href=\"#_ednref1\" name=\"_edn1\">[1]<\/a> \u201c<a href=\"https:\/\/www.dhs.gov\/science-and-technology\/critical-infrastructure\" target=\"_blank\" rel=\"noopener\">Critical Infrastructure<\/a>.\u201d <em>The U.S. Department of Homeland Security<\/em>. Retrieved 2022-03-01.<\/p>\n<p><a href=\"#_ednref2\" name=\"_edn2\">[2]<\/a> \u201c<a href=\"https:\/\/www.cisa.gov\/critical-infrastructure-sectors\" target=\"_blank\" rel=\"noopener\">Critical Infrastructure Sectors<\/a>.\u201d <em>The U.S. Cybersecurity &amp; Infrastructure Security Agency<\/em>. Retrieved 2022-03-01.<\/p>\n<p><a href=\"#_ednref3\" name=\"_edn3\">[3]<\/a> \u201c<a href=\"https:\/\/www.cisa.gov\/energy-sector\" target=\"_blank\" rel=\"noopener\">Energy Sector<\/a>.\u201d <em>The U.S. Cybersecurity &amp; Infrastructure Security Agency<\/em>. Retrieved 2022-03-01.<\/p>\n<p><a href=\"#_ednref4\" name=\"_edn4\">[4]<\/a> \u201c<a href=\"https:\/\/www2.deloitte.com\/us\/en\/pages\/energy-and-resources\/articles\/power-and-utilities-industry-outlook.html\" target=\"_blank\" rel=\"noopener\">2022 power and utilities industry outlook: The clean energy transition powers on<\/a>.\u201d <em>Deloitte<\/em>. Retrieved 2022-03-01.<\/p>\n<p><a href=\"#_ednref5\" name=\"_edn5\">[5]<\/a> \u201c<a href=\"https:\/\/www.iea.org\/news\/surging-electricity-demand-is-putting-power-systems-under-strain-around-the-world\" target=\"_blank\" rel=\"noopener\">Surging electricity demand is putting power systems under strain around the world<\/a>.\u201d <em>The International Energy Agency<\/em>. Published 2022-01-14. Retrieved 2022-03-01.<\/p>\n<p><a href=\"#_ednref6\" name=\"_edn6\">[6]<\/a> Ibid.<\/p>\n<p><a href=\"#_ednref7\" name=\"_edn7\">[7]<\/a> \u201c<a href=\"https:\/\/crsreports.congress.gov\/product\/pdf\/R\/R46959\" target=\"_blank\" rel=\"noopener\">Evolving Electric Power Systems and Cybersecurity<\/a>.\u201d <em>U.S. Congressional Research Service<\/em>. Published 2021-11-04. Retrieved 2022-03-01.<\/p>\n<p><a href=\"#_ednref8\" name=\"_edn8\">[8]<\/a> Cimpanu, Catalin. \u201c<a href=\"https:\/\/www.zdnet.com\/article\/uk-electricity-middleman-hit-by-cyber-attack\/\" target=\"_blank\" rel=\"noopener\">UK electricity middleman hit by cyber-attack<\/a>.\u201d <em>ZDNet<\/em>. Published 2020-05-14. Retrieved 2022-03-01.<\/p>\n<p><a href=\"#_ednref9\" name=\"_edn9\">[9]<\/a> Zetter, Kim. \u201c<a href=\"https:\/\/www.wired.com\/2016\/03\/inside-cunning-unprecedented-hack-ukraines-power-grid\/\" target=\"_blank\" rel=\"noopener\">Inside the Cunning, Unprecedented Hack of Ukraine&#8217;s Power Grid<\/a>.\u201d <em>WIRED<\/em>. Published 2016-03-03. Retrieved 2022-03-01.<\/p>\n<p><a href=\"#_ednref10\" name=\"_edn10\">[10]<\/a> Gordon, Jonathan. \u201c<a href=\"https:\/\/industrialcyber.co\/essential-guides\/the-essential-guide-to-the-iec-62443-industrial-cybersecurity-standards\/\" target=\"_blank\" rel=\"noopener\">The Essential Guide to the IEC 62443 industrial cybersecurity standards<\/a>.\u201d <em>Industrial Cyber<\/em>. Published 2021-12-26. Retrieved 2022-03-01.<\/p>\n<p><a href=\"#_ednref11\" name=\"_edn11\">[11]<\/a> Sanchez, Michael. \u201c<a href=\"https:\/\/www.hstoday.us\/subject-matter-areas\/infrastructure-security\/10-essential-steps-to-cyber-resilience-as-hackers-target-critical-infrastructure\/\" target=\"_blank\" rel=\"noopener\">10 Essential Steps to Cyber Resilience as Hackers Target Critical Infrastructure<\/a>.\u201d <em>Homeland Security Today<\/em>. Published 2021-03-18. Retrieved 2022-03-01.<\/p>\n<p><a href=\"#_ednref12\" name=\"_edn12\">[12]<\/a> Bailey, Tucker. \u201c<a href=\"https:\/\/www.mckinsey.com\/business-functions\/risk-and-resilience\/our-insights\/the-energy-sector-threat-how-to-address-cybersecurity-vulnerabilities\" target=\"_blank\" rel=\"noopener\">The energy-sector threat: How to address cybersecurity vulnerabilities<\/a>.\u201d <em>McKinsey<\/em>. Published 2020-11-03. Retrieved 2022-03-01.<\/p>\n<p><a href=\"#_ednref13\" name=\"_edn13\">[13]<\/a> Livingston, Steve, et all. \u201c<a href=\"https:\/\/www2.deloitte.com\/content\/dam\/insights\/us\/articles\/4921_Managing-cyber-risk-Electric-energy\/DI_Managing-cyber-risk.pdf\" target=\"_blank\" rel=\"noopener\">Managing cyber risk in the electric power sector Emerging threats to supply chain and industrial control systems.<\/a>\u201d <em>Deloitte<\/em>. Retrieved 2022-03-01.<\/p>\n<\/div><\/div><\/div><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":3,"featured_media":0,"parent":3650,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"100-width.php","meta":{"footnotes":""},"categories":[],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v22.0 (Yoast SEO v23.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Cybersecurity in the Electricity Industry - kw022024<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/itegriti.com\/kw022024\/expertise\/cybersecurity-in-the-electricity-industry\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cybersecurity in the Electricity Industry\" \/>\n<meta property=\"og:url\" content=\"https:\/\/itegriti.com\/kw022024\/expertise\/cybersecurity-in-the-electricity-industry\/\" \/>\n<meta property=\"og:site_name\" content=\"kw022024\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/itegriti\" \/>\n<meta property=\"article:modified_time\" content=\"2022-10-02T17:06:19+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@itegriti\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/expertise\/cybersecurity-in-the-electricity-industry\/\",\"url\":\"https:\/\/itegriti.com\/kw022024\/expertise\/cybersecurity-in-the-electricity-industry\/\",\"name\":\"Cybersecurity in the Electricity Industry - kw022024\",\"isPartOf\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/#website\"},\"datePublished\":\"2022-10-02T06:06:48+00:00\",\"dateModified\":\"2022-10-02T17:06:19+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/expertise\/cybersecurity-in-the-electricity-industry\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/itegriti.com\/kw022024\/expertise\/cybersecurity-in-the-electricity-industry\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/expertise\/cybersecurity-in-the-electricity-industry\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/itegriti.com\/kw022024\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Expertise\",\"item\":\"https:\/\/itegriti.com\/kw022024\/expertise\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Cybersecurity in the Electricity Industry\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/#website\",\"url\":\"https:\/\/itegriti.com\/kw022024\/\",\"name\":\"ITEGRITI\",\"description\":\"cybersecurity | compliance | managed services\",\"publisher\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/itegriti.com\/kw022024\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/#organization\",\"name\":\"ITEGRITI CORPORATION | Cybersecurity | Compliance | Managed Services\",\"url\":\"https:\/\/itegriti.com\/kw022024\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/itegriti.com\/kw022024\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2016\/06\/ItegritiLogo_600x100.png\",\"contentUrl\":\"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2016\/06\/ItegritiLogo_600x100.png\",\"width\":600,\"height\":100,\"caption\":\"ITEGRITI CORPORATION | Cybersecurity | Compliance | Managed Services\"},\"image\":{\"@id\":\"https:\/\/itegriti.com\/kw022024\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/itegriti\",\"https:\/\/x.com\/itegriti\",\"https:\/\/www.linkedin.com\/company\/itegriti\/\"]}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Cybersecurity in the Electricity Industry - kw022024","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/itegriti.com\/kw022024\/expertise\/cybersecurity-in-the-electricity-industry\/","og_locale":"en_US","og_type":"article","og_title":"Cybersecurity in the Electricity Industry","og_url":"https:\/\/itegriti.com\/kw022024\/expertise\/cybersecurity-in-the-electricity-industry\/","og_site_name":"kw022024","article_publisher":"https:\/\/www.facebook.com\/itegriti","article_modified_time":"2022-10-02T17:06:19+00:00","twitter_card":"summary_large_image","twitter_site":"@itegriti","twitter_misc":{"Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/itegriti.com\/kw022024\/expertise\/cybersecurity-in-the-electricity-industry\/","url":"https:\/\/itegriti.com\/kw022024\/expertise\/cybersecurity-in-the-electricity-industry\/","name":"Cybersecurity in the Electricity Industry - kw022024","isPartOf":{"@id":"https:\/\/itegriti.com\/kw022024\/#website"},"datePublished":"2022-10-02T06:06:48+00:00","dateModified":"2022-10-02T17:06:19+00:00","breadcrumb":{"@id":"https:\/\/itegriti.com\/kw022024\/expertise\/cybersecurity-in-the-electricity-industry\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/itegriti.com\/kw022024\/expertise\/cybersecurity-in-the-electricity-industry\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/itegriti.com\/kw022024\/expertise\/cybersecurity-in-the-electricity-industry\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/itegriti.com\/kw022024\/"},{"@type":"ListItem","position":2,"name":"Expertise","item":"https:\/\/itegriti.com\/kw022024\/expertise\/"},{"@type":"ListItem","position":3,"name":"Cybersecurity in the Electricity Industry"}]},{"@type":"WebSite","@id":"https:\/\/itegriti.com\/kw022024\/#website","url":"https:\/\/itegriti.com\/kw022024\/","name":"ITEGRITI","description":"cybersecurity | compliance | managed services","publisher":{"@id":"https:\/\/itegriti.com\/kw022024\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/itegriti.com\/kw022024\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/itegriti.com\/kw022024\/#organization","name":"ITEGRITI CORPORATION | Cybersecurity | Compliance | Managed Services","url":"https:\/\/itegriti.com\/kw022024\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/itegriti.com\/kw022024\/#\/schema\/logo\/image\/","url":"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2016\/06\/ItegritiLogo_600x100.png","contentUrl":"https:\/\/itegriti.com\/kw022024\/wp-content\/uploads\/2016\/06\/ItegritiLogo_600x100.png","width":600,"height":100,"caption":"ITEGRITI CORPORATION | Cybersecurity | Compliance | Managed Services"},"image":{"@id":"https:\/\/itegriti.com\/kw022024\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/itegriti","https:\/\/x.com\/itegriti","https:\/\/www.linkedin.com\/company\/itegriti\/"]}]}},"_links":{"self":[{"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/pages\/3675"}],"collection":[{"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/comments?post=3675"}],"version-history":[{"count":3,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/pages\/3675\/revisions"}],"predecessor-version":[{"id":3773,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/pages\/3675\/revisions\/3773"}],"up":[{"embeddable":true,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/pages\/3650"}],"wp:attachment":[{"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/media?parent=3675"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/categories?post=3675"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itegriti.com\/kw022024\/wp-json\/wp\/v2\/tags?post=3675"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}